Sample viewer

vx.netlux.org/Virus.DOS.HLLO.Ondra.4912

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:35.645840844Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:35.64717527Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:35.652693506Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:35.667289473Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:35.669038058Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:35.671426124Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:35.673351751Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:35.674993425Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:35.677174442Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:35.690729193Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:35.692602211Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:35.694408985Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:35.697309163Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:35.699062567Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:35.701305009Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:35.714126263Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:35.715994132Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:35.717860187Z 53 PC: 130f6 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:35.720081349Z 37 PC: 1310b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:35.721678039Z 37 PC: 13113 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:35.723239912Z 37 PC: 1311b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:35.73398737Z 37 PC: 13123 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:35.736027904Z 68 PC: 1373b | I/O control for devices (Set for = '')
2018-12-17T22:53:35.738279353Z 98 PC: 12f65 | Get current PSP
2018-12-17T22:53:35.740107607Z 51 PC: 12fa9 | Get or set Ctrl-Break
2018-12-17T22:53:35.742573569Z 26 PC: 1305a | Set disk transfer address
2018-12-17T22:53:35.743980692Z 78 PC: 13066 | Find first file
2018-12-17T22:53:35.752293077Z 26 PC: 1307e | Set disk transfer address
2018-12-17T22:53:35.754784717Z 79 PC: 13083 | Find next file
2018-12-17T22:53:35.758170777Z 26 PC: 1307e | Set disk transfer address
2018-12-17T22:53:35.760558673Z 79 PC: 13083 | Find next file
2018-12-17T22:53:35.76454485Z 26 PC: 1307e | Set disk transfer address
2018-12-17T22:53:35.766112715Z 79 PC: 13083 | Find next file
2018-12-17T22:53:35.76947949Z 26 PC: 1307e | Set disk transfer address
2018-12-17T22:53:35.77929078Z 79 PC: 13083 | Find next file
2018-12-17T22:53:35.783447668Z 26 PC: 1307e | Set disk transfer address
2018-12-17T22:53:35.784672549Z 79 PC: 13083 | Find next file
2018-12-17T22:53:35.788497774Z 26 PC: 1307e | Set disk transfer address
2018-12-17T22:53:35.789742582Z 79 PC: 13083 | Find next file
2018-12-17T22:53:35.792687935Z 26 PC: 1307e | Set disk transfer address
2018-12-17T22:53:35.794302879Z 79 PC: 13083 | Find next file
2018-12-17T22:53:35.79795596Z 26 PC: 1307e | Set disk transfer address
2018-12-17T22:53:35.79947265Z 79 PC: 13083 | Find next file
2018-12-17T22:53:35.817563191Z 67 PC: 12fe3 | Get or set file attributes
2018-12-17T22:53:35.836917587Z 61 PC: 13a5d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:53:35.845314349Z 61 PC: 13a5d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:53:35.852769313Z 63 PC: 13aef | Read file or device (Read 100 bytes on handle 5)
2018-12-17T22:53:35.856428226Z 63 PC: 13aef | Read file or device (Read 100 bytes on handle 6)
2018-12-17T22:53:35.859598852Z 62 PC: 13aad | Close file
2018-12-17T22:53:35.861985014Z 62 PC: 13aad | Close file
2018-12-17T22:53:35.86558662Z 67 PC: 12fe3 | Get or set file attributes
2018-12-17T22:53:35.876631847Z 26 PC: 1307e | Set disk transfer address
2018-12-17T22:53:35.878248955Z 79 PC: 13083 | Find next file
2018-12-17T22:53:35.882640574Z 26 PC: 1305a | Set disk transfer address
2018-12-17T22:53:35.884539732Z 78 PC: 13066 | Find first file